Skip to content

New EU Rules for Smart Products: Cybersecurity Becomes Mandatory

Connected household appliances, fitness trackers, smart heating systems and modern industrial facilities: more and more products are connected to the internet. At the same time, the risk of criminals exploiting security vulnerabilities continues to grow. The European Union has responded with the Cyber Resilience Act (CRA). A key milestone came into force around a month ago.

8 October 2026

From vacuum cleaners to smartwatches: manufacturers must now report security vulnerabilities

Connected household appliances, fitness trackers, smart heating systems and modern production facilities: more and more products are connected to the internet. At the same time, the risk of criminals exploiting security vulnerabilities is increasing. The European Union is responding to this with the Cyber Resilience Act (CRA). A key milestone came into force around a month ago (effective 11 September 2026): manufacturers must now report actively exploited vulnerabilities and serious security incidents within short timeframes.

For consumers, this is intended to enhance the security of digital products. For businesses, however, the new regulation means there is a significant need for action. Many manufacturers must introduce new processes to be able to identify, analyse and rectify security vulnerabilities at an early stage.

Digital security is becoming part of product quality

“Product safety no longer ends with material quality or technical function,” says Matthias Springer, Senior Vice President of Functional Safety & Security at TÜV NORD. “A product’s digital security is also increasingly becoming a quality feature.”

Almost all products with digital elements are affected. These include, for example, smart home applications, routers, apps, wearables and connected machines. Anyone who fails to comply with the European requirements in future risks fines and, under certain circumstances, may no longer be able to offer products on the European market.

Many companies underestimate the effort involved

The new reporting obligations are only part of the requirements. In future, manufacturers must be able to demonstrate that cybersecurity has been taken into account right from the development stage. Furthermore, security updates must be provided and vulnerabilities monitored throughout the entire product lifecycle.

“In order to meet the reporting requirements now, the necessary processes must be established and effectively implemented. Furthermore, cybersecurity must be permanently embedded in business processes and product development,” says Michelle Michael, Lead Expert for Secure Digital Solutions at TÜVIT.

Building expertise, testing processes, securing products

The TÜV NORD GROUP supports companies in this regard at various levels: from training courses and workshops, through assessments of crisis and vulnerability management processes, to technical security audits and certifications.

“Cybersecurity is increasingly becoming a competitive factor,” says Springer. “Consumers expect secure products. Companies that act early on build trust and are better prepared for future requirements.”

With the full implementation of the Cyber Resilience Act at the end of 2027, cybersecurity will finally become a prerequisite for access to the European market for many connected products.

Further information is available here: CRA: Cybersecurity of connected devices | TÜVIT

About the TÜV NORD GROUP

Founded over 150 years ago, we are recognised worldwide as a symbol of security and trust. As a knowledge-based company, we have our sights firmly set on the digital future. Whether it’s female engineers, IT security experts or specialists in the mobility of the future: in more than 100 countries, we ensure that our customers become even more successful in our connected world.

Contact

Stefan Genz, Konzern-Kommunikation von der TÜV NORD GROUP

Stefan Genz

Digital & Semiconductor (IT, Space)